Agent skill

API Security Hardening

by secondsky in secondsky/claude-skills

REST API security hardening with authentication, rate limiting, input validation, security headers.

MITAuto-check passedSecurity

Install API Security Hardening

skills CLI
$ npx skills add secondsky/claude-skills --skill api-security-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/claude-skills api-security-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/api-security-hardening/skills/api-security-hardening .claude/skills/api-security-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-security-hardening
GitHub stars
227
Token cost
~718 tokens
SKILL.md length
107 words
Files
2 (incl. references)
Skills in repo
168
Repo updated
First seen
Licence
MIT

At a glance

REST API security hardening with authentication, rate limiting, input validation, security headers.

  • Production APIs
  • SKILL.md covers Security Middleware Stack…, Input Validation, Security Headers and Security Checklist, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Security audits

What it does

API Security Hardening is an agent skill from secondsky/claude-skills. REST API security hardening with authentication, rate limiting, input validation, security headers. Use for production APIs, security audits, defense-in-depth, or encountering vulnerabilities, injection attacks, CORS issues.

Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/python-nginx.md`).

It sits in Security, covering Security review and Secure coding. It works with NGINX and Python. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • Production APIs
  • Security audits
  • Defense-in-depth
  • Encountering vulnerabilities

Example prompts

  • “/api-security-hardening”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Security Hardening loads about 718 tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 107 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~718
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 107 words, ~718 tokens.

Download SKILL.mdSave it as .claude/skills/api-security-hardening/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
api-security-hardening
description
REST API security hardening with authentication, rate limiting, input validation, security headers. Use for production APIs, security audits, defense-in-depth, or encountering vulnerabilities, injection attacks, CORS issues.
license
MIT

API Security Hardening

Protect REST APIs against common vulnerabilities with multiple security layers.

Security Middleware Stack (Express)

javascript
const helmet = require('helmet');
const rateLimit = require('express-rate-limit');
const mongoSanitize = require('express-mongo-sanitize');

app.use(helmet());
app.use(mongoSanitize());
// For input sanitization, see the `xss-prevention` skill — do NOT use the
// deprecated `xss-clean` package (unmaintained since 2018; its own README
// recommends migrating off it).

app.use('/api/', rateLimit({
  windowMs: 15 * 60 * 1000,
  max: 100
}));

app.use('/api/auth/', rateLimit({
  windowMs: 15 * 60 * 1000,
  max: 5
}));

Input Validation

javascript
const { body, validationResult } = require('express-validator');
const escapeHtml = require('escape-html');

app.post('/users',
  body('email').isEmail().normalizeEmail(),
  body('password').isLength({ min: 8 }).matches(/[A-Z]/).matches(/[0-9]/),
  // express-validator v7+ removed the built-in .escape() sanitizer; use a
  // customSanitizer backed by `escape-html` to HTML-escape the value.
  body('name').trim().isLength({ max: 100 }).customSanitizer(v => escapeHtml(v)),
  (req, res) => {
    const errors = validationResult(req);
    if (!errors.isEmpty()) {
      return res.status(400).json({ errors: errors.array() });
    }
    // Process request
  }
);

Security Headers

javascript
app.use((req, res, next) => {
  res.setHeader('Content-Security-Policy', "default-src 'self'");
  res.setHeader('X-Frame-Options', 'DENY');
  res.setHeader('X-Content-Type-Options', 'nosniff');
  res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
  res.setHeader('X-XSS-Protection', '1; mode=block');
  next();
});

Security Checklist

  • HTTPS everywhere
  • Authentication on all protected routes
  • Input validation and sanitization
  • Rate limiting enabled
  • Security headers configured
  • CORS restricted to allowed origins
  • No stack traces in production errors
  • Audit logging enabled
  • Dependencies regularly updated

Additional Implementations

See references/python-nginx.md for:

  • Python FastAPI security middleware
  • Pydantic input validation with password rules
  • Nginx SSL/TLS and security headers configuration
  • HTTP Parameter Pollution prevention

Never Do

  • Trust user input without validation
  • Return detailed errors in production
  • Store secrets in code
  • Use GET for state-changing operations
  • Disable security for convenience

© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/api-security-hardening/skills/api-security-hardening of secondsky/claude-skills.

  • SKILL.md
  • references/python-nginx.md

Open the folder on GitHubat commit 8837836

Compare with similar skills

API Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Security Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Security Hardening this skillsecondsky/claude-skills227—~718Automated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Python kwargs setattr Allowlistmicrosoft/onnxruntime22k—~737Automated safety check: PassMIT
Cb Security HardeningBlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT
Agent-Core Security ChecklistopenJiuwen-ai/agent-core446—~1.7kAutomated safety check: NotesApache-2.0

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Python kwargs setattr Allowlist

    microsoft/onnxruntime

    Official

    Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects.

    22k GitHub stars~737 tokensUpdated today
    SecurityAuto-check passed
  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Agent-Core Security Checklist

    openJiuwen-ai/agent-core

    A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

    446 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review Checklist

    ZeroDeng01/sublinkPro

    Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

    1.7k GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed

More from secondsky/claude-skills

All 168 skills in this repo
  • Auto Animate

    secondsky/claude-skills

    AutoAnimate (@formkit/auto-animate) zero-config animations for React.

    227 GitHub stars~2.9k tokensUpdated 11 days ago
    Auto-check passed
  • Base UI React

    secondsky/claude-skills

    MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 11 days ago
    Auto-check passed
  • Cloudflare Images

    secondsky/claude-skills

    This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…

    227 GitHub stars~3.6k tokensUpdated 11 days ago
    Auto-check: notes
  • Cloudflare Nextjs

    secondsky/claude-skills

    Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).

    227 GitHub stars~5.3k tokensUpdated 11 days ago
    Auto-check: notes
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 11 days ago
    Auto-check passed
  • GitHub Project Automation

    secondsky/claude-skills

    GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL).

    227 GitHub stars~4k tokensUpdated 11 days ago
    Auto-check: notes

Works with

Questions about API Security Hardening

What does API Security Hardening do?

REST API security hardening with authentication, rate limiting, input validation, security headers. API Security Hardening is an agent skill from secondsky/claude-skills. REST API security hardening with authentication, rate limiting, input validation, security headers.

When should I use API Security Hardening?

API Security Hardening fits situations like: production APIs; security audits; defense-in-depth; encountering vulnerabilities.

How do I install API Security Hardening in Claude Code?

Run `npx skills add secondsky/claude-skills --skill api-security-hardening -a claude-code`. Or copy the skill folder (plugins/api-security-hardening/skills/api-security-hardening in secondsky/claude-skills) into .claude/skills/api-security-hardening in your project. Claude Code loads it when a task matches its description.

How do I install API Security Hardening in Codex?

Run `npx skills add secondsky/claude-skills --skill api-security-hardening -a codex`. Or copy the skill folder (plugins/api-security-hardening/skills/api-security-hardening in secondsky/claude-skills) into .agents/skills/api-security-hardening in your project. Codex loads it when a task matches its description.

Can I use API Security Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill api-security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-security-hardening, .gemini/skills/api-security-hardening, .github/skills/api-security-hardening and .opencode/skills/api-security-hardening in your project.

What does API Security Hardening need to run?

SKILL.md names no scripts, command-line tools or credentials: API Security Hardening is instructions for the agent only. Our summary lists: Python 3.

Does API Security Hardening access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Security Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Security Hardening use?

API Security Hardening is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Security Hardening use?

About 718 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to API Security Hardening?

Skills that share tags, products or a category with API Security Hardening: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Python kwargs setattr Allowlist (microsoft/onnxruntime, 22k stars) and Cb Security Hardening (BlkLeg/CircuitBreaker, 201 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Security Hardening?

secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 168 skills in this directory. The repository was last updated on September 28, 2026.

Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.